CVE-2025-36539: AVEVA PI Data Archive Uncaught Exception

Published Jun 12, 2025
·
Updated

AVEVA PI Data Archive products are vulnerable to an uncaught exception that, if exploited, could allow an authenticated user to shut down certain necessary PI Data Archive subsystems, resulting in a denial of service.

Affected Software

6 affected components
: AVEVA PI Data Archive: Versions 2018 SP3 Patch 4 and prior (CVE-2025-44019)
: AVEVA PI Data Archive: Version 2023 (CVE-2025-44019, CVE-2025-36539)
: AVEVA PI Data Archive: Version 2023 Patch 1 (CVE-2025-44019, CVE-2025-36539)
: AVEVA PI Server: Versions 2018 SP3 Patch 6 and prior (CVE-2025-44019)
: AVEVA PI Server: Version 2023 (CVE-2025-44019, CVE-2025-36539)
: AVEVA PI Server: Version 2023 Patch 1 (CVE-2025-44019, CVE-2025-36539)

Remediation

Information

AVEVA recommends that organizations evaluate the impact of these vulnerabilities based on their operational environment, architecture, and product implementation. Users with affected product versions should apply security updates to mitigate the risk of exploit. All affected versions of PI Data Archive and PI Server can be fixed by upgrading to PI Server 2024 or higher. From OSISoft Customer Portal https://my.osisoft.com/ , search for "AVEVA PI Server" and select version 2024 or higher. For additional information please refer to AVEVA-2025-001 https://www.aveva.com/en/support-and-success/cyber-security-updates/ .

Event History

Jun 12, 2025
CVE Published
via MITRE·07:56 PM
Data Sourced
via MITRE·07:56 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-36539?

CVE-2025-36539 has a high severity rating since it allows authenticated users to trigger a denial of service by shutting down critical subsystems.

2

How do I fix CVE-2025-36539?

To fix CVE-2025-36539, you should upgrade to the latest version of AVEVA PI Data Archive or PI Server that is patched against this vulnerability.

3

Who is affected by CVE-2025-36539?

CVE-2025-36539 affects users of AVEVA PI Data Archive versions up to 2018 SP3 Patch 4 and all versions of AVEVA PI Server prior to the latest patches.

4

What is the impact of exploiting CVE-2025-36539?

Exploiting CVE-2025-36539 can result in a denial of service, impacting the availability of essential PI Data Archive subsystems.

5

Are there any workarounds for CVE-2025-36539?

Currently, no specific workarounds are recommended for CVE-2025-36539 besides applying the necessary updates as soon as possible.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203